AML KYC Sanctions Policy

Last updated: September 17, 2026

ANTI-MONEY LAUNDERING, KNOW-YOUR-CLIENT AND SANCTIONS POLICY

SABAI ECOVERSE PTE. LTD.

Version 1.0

Effective: 01 October 2025

1. PURPOSE AND SCOPE

1.1. SABAI ECOVERSE PTE. LTD., a private limited company incorporated in Singapore, UEN 202346091R, operating under the "Sabai Protocol" brand (the "Company", "we", "us"), does not accept money or other assets that may be connected with crime, and does not provide services to persons who seek to use them to launder money, finance terrorism or the proliferation of weapons of mass destruction, evade sanctions, commit fraud or mislead investors.

1.2. This Policy summarises the measures the Company applies for this purpose. It applies to all clients and prospective clients, persons paying on their behalf, collection agents, partners and suppliers, and to the Company's staff and subcontractors.

1.3. This Policy supplements Sections 4, 5, 6 and 7 of our Terms of Service (Public Offer) published at https://sabaiprotocol.com/terms-of-service (the "Terms").

2. OUR REGULATORY STATUS

2.1. The Company provides business consulting and software development services. It is not a bank, payment service provider, digital token service provider or other financial institution, and it is not licensed or regulated by the Monetary Authority of Singapore.

2.2. The measures described in this Policy are applied by the Company voluntarily, on a risk-based approach, in line with the international standards of the Financial Action Task Force (FATF) and the requirements of the banks, payment institutions and digital-asset service providers with which the Company works.

2.3. The Company complies with the obligations that Singapore law places on every business, including the duty to report suspicious transactions under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 and the Terrorism (Suppression of Financing) Act 2002, and the prohibitions on dealing with designated persons under Singapore law.

3. RISK-BASED APPROACH

3.1. Before and during each engagement, we assess the risk that the engagement or the payment may be connected with financial crime. We take into account, in particular:

(a) the type of client, its ownership and control structure and its business;

(b) the countries connected with the client, its owners and the project;

(c) the nature of the services and of the client's project, including whether the project involves raising funds from investors or issuing tokens;

(d) the payment method, the amount and the origin of the funds, including payments in digital assets and payments by third parties;

(e) any information from public sources and screening results.

3.2. The scope of our checks depends on the assessed risk. For low-risk engagements, checks may be limited to identifying the client and screening it against sanctions lists.

4. KNOW-YOUR-CLIENT MEASURES

4.1. Identification. We may request:

(a) from individuals: full name, date of birth, nationality, residential address and a copy of an identity document;

(b) from legal entities: registered name, registration number, registered address, certificate of incorporation or an extract from the register, information on directors, authorised representatives and beneficial owners (individuals who ultimately own or control, directly or indirectly, 25% or more of the entity or otherwise control it), and identification of the person placing the order;

(c) information on the purpose and nature of the engagement and of the client's project.

4.2. Enhanced measures. Where the risk is higher, we may additionally request information and documents on the source of funds and, where relevant, the source of wealth, verify information through additional sources, and require approval by the Company's management before starting or continuing the engagement. Higher risk includes, in particular:

(a) politically exposed persons, their family members and close associates;

(b) connections with jurisdictions identified by the FATF as high-risk or subject to increased monitoring;

(c) complex or unusual ownership structures without a clear business reason;

(d) unusually large or unusually structured payments, or payments by third parties;

(e) projects that involve offering tokens or other investments to the public.

4.3. Ongoing monitoring. We monitor engagements and payments for consistency with what we know about the client, and we may ask the client to update its information at any time.

5. SANCTIONS

5.1. We screen clients, their beneficial owners and, where relevant, payers and counterparties against the sanctions lists of the United Nations, Singapore, the European Union, the United Kingdom and the United States.

5.2. We do not enter into or continue engagements with, and do not accept payments from or make payments to: (a) persons subject to such sanctions; (b) persons located, incorporated or ordinarily resident in jurisdictions or territories subject to comprehensive sanctions; or (c) persons acting on behalf of or for the benefit of any of them.

5.3. We do not provide services intended to help any person circumvent sanctions.

6. PAYMENTS AND DIGITAL ASSETS

6.1. Payments are accepted only by bank transfer or in digital assets accepted by the Company, and only to the account details, deposit addresses or payment links stated in the invoice. We do not accept cash.

6.2. Incoming payments in digital assets are screened by the Company and its digital-asset service providers. We may reject a payment where the sending address or an intermediary is associated with sanctioned persons, darknet markets, mixing services, fraud, theft, ransomware or other illicit or high-risk activity.

6.3. Payments by a third party on the client's behalf are accepted only with our prior written consent and after identification of the payer, as provided in Section 5.6 of the Terms.

6.4. A rejected payment is returned, where technically and legally possible, to the originating account or address, net of transaction costs. Refunds are made only to the account or address from which the payment was received.

7. OUR SERVICES AND CLIENT PROJECTS

7.1. We do not provide services for projects designed to evade financial regulation, sanctions or tax obligations, or to mislead investors.

7.2. Where we develop or configure software for a client's platform, including identification, screening or payment modules, the client remains solely responsible for obtaining the licences required for its activity and for complying with anti-money laundering, know-your-client and sanctions requirements applicable to its platform and its users.

8. REFUSAL, SUSPENSION AND TERMINATION

8.1. We may decline an order, suspend an engagement or terminate the agreement, as provided in Sections 4.3, 7.2 and 14.2 of the Terms, if: (a) the client does not provide requested information or documents within a reasonable period; (b) the information provided is false, incomplete or inconsistent; (c) screening results are unsatisfactory; or (d) we have reasonable grounds to suspect that the engagement or a payment is connected with financial crime or sanctions evasion.

8.2. We are not obliged to explain the reasons for such a decision where the explanation could breach the law or prejudice an investigation.

9. REPORTING

9.1. Where we know or have reasonable grounds to suspect that property or a transaction is connected with criminal conduct or terrorism financing, we report it to the Suspicious Transaction Reporting Office of the Singapore Police Force or to another competent authority, as required by law.

9.2. We do not inform the person concerned that a report has been made or is being considered where the law prohibits such disclosure.

10. RECORD KEEPING

10.1. We keep identification documents, screening results, records of payments and related correspondence for five years after the end of the business relationship or after the relevant transaction, or longer where required by law.

11. STAFF AND SUBCONTRACTORS

11.1. The Company's management is responsible for this Policy. Staff and subcontractors involved in client onboarding and payments are informed of this Policy, must follow it, must report any suspicion internally without delay, and are bound by confidentiality.

12. PERSONAL DATA

12.1. Personal data collected under this Policy is processed in accordance with our Privacy Policy published at https://sabaiprotocol.com/privacy-policy.

13. REVIEW OF THIS POLICY

13.1. We review this Policy at least once a year and whenever our services, payment methods or applicable requirements change. This Policy is identified by the version number and effective date stated at the head of this document. Previous versions are retained by the Company.

13.2. Translations of this Policy are provided for convenience; the English version prevails.

14. CONTACT

SABAI ECOVERSE PTE. LTD.

UEN 202346091R

531 Upper Cross Street, #02-11, Hong Lim Complex, Singapore 050531

Email: it@sabaifriends.com

Website: https://sabaiprotocol.com